
CVE-2022-40684
Proof-of-concept exploit for CVE-2022-40684 authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager. Injects SSH keys via…

Proof-of-concept exploit for CVE-2022-40684 authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager. Injects SSH keys via…

Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.

SSH Exploit Tool (Educational Use Only) 📌 Description This tool demonstrates exploitation of: CVE-2008-0166 CVE-2008-1657 It connects to vulnerable…

Proof-of-concept exploit for CVE-2025-32433, a pre-authentication RCE in Erlang/OTP SSH daemon. Includes Python script to send crafted SSH channel…

Missing Authentication for Critical Function (CWE-306)-Exploit

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts

SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

Python proof-of-concept for CVE-2026-67401, an authenticated SQL injection in cPanel EmailTrack that allows arbitrary file write as root via SQLite…

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

Proof of concept python script for regreSSHion exploit.

Python-based exploit for CVE-2018-15473, enabling SSH user enumeration via OpenSSH username validation timing attack. Updated from Python 2 to 3 for…

A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4

Proof of concept (POC) for CVE-2024-45337

rewrited SSH Exploit for CVE-2024-6387 (regreSSHion)

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…